MAS PS-G04 Audit Readiness Guide for PSPs (2026)

Compliance officer reviewing MAS PS-G04 audit readiness checklist for a Singapore payment service provider

MAS PS-G04 Audit Readiness: What Singapore Payment Service Providers Need to Prepare For

Introduction

From 16 July 2026, the annual audit that every licensed payment service provider in Singapore already budgets for changes in substance, even if the paperwork looks familiar. The Monetary Authority of Singapore has issued PS-G04, a guideline that pushes external auditors well beyond checking that financial statements are accurate.

Auditors are now expected to test whether your AML/CFT controls, safeguarding arrangements, technology risk framework and regulatory reporting actually work in practice, and whether issues raised in prior years were genuinely closed out. For compliance officers and MLROs, this means the groundwork for a clean audit now starts months earlier than it used to.

This guide walks through what PS-G04 requires, where MAS auditors will focus, and the practical steps Pecuniya recommends taking before your audit window opens.

Executive Summary

  • PS-G04 takes effect on 16 July 2026 and applies to all licensed payment service providers under the Payment Services Act.
  • MAS now expects the annual audit to test regulatory compliance, risk management and internal controls, not just confirm that filings were made.
  • Six areas will receive close scrutiny: AML/CFT controls, safeguarding of customer monies, base capital compliance, technology risk and cyber resilience, accuracy of MAS regulatory reporting, and remediation of prior findings.
  • Newly licensed PSPs face an additional end-to-end review of AML/CFT and technology risk controls one year after operations begin.
  • Auditors are expected to test operating effectiveness through sample testing and substantive review — documentation that a control exists on paper is no longer enough.
  • Early preparation, rather than a scramble in the weeks before the auditor arrives, is what separates a smooth audit cycle from a stressful one.

Why This Regulatory Update Matters

Every licensed PSP is already required to appoint a qualified external auditor each financial year, lodge Form 4 within six months of financial year-end, furnish audited financial statements, submit an Independent Assurance Report, and provide MAS with the auditor’s findings, observations and management letter.

PS-G04 does not remove any of these obligations. What it changes is the depth of what the audit is expected to cover. Rather than treating the audit as a filing exercise, MAS has set out its expectation that the audit itself becomes a mechanism for testing whether a PSP’s compliance and risk management framework functions as intended.

This matters because it shifts the burden onto the PSP well before the auditor’s fieldwork begins. If evidence of a control’s operation cannot be produced quickly and clearly, that gap itself becomes an audit observation — regardless of whether the underlying control is sound.

Who Is Affected

  • Licensed payment service providers under the Payment Services Act, across all licence classes.
  • Newly licensed PSPs and existing PSPs adding a newly licensed payment service, who face additional first-year review requirements.
  • Compliance, risk, internal audit, technology and finance functions that will need to produce evidence on request.
  • Boards and senior management, who remain accountable for the effectiveness of the control environment MAS is testing.

Business Implications

  • Audit preparation becomes a year-round discipline rather than a pre-audit sprint.
  • Documentation and evidence trails need to be maintained continuously, not reconstructed retrospectively.
  • Prior audit and inspection findings need a formal tracking mechanism through to verified closure.
  • Technology risk and AML/CFT functions should expect more detailed, evidence-based auditor requests than in previous cycles.

Key Regulatory Changes

The table below summarises how the audit expectation shifts under PS-G04 compared with the position PSPs have generally worked to until now.

Area Before PS-G04 Under PS-G04
Audit scope Confirm financial statements, Form 4 lodgement and Independent Assurance Report are filed Additionally test regulatory compliance, risk management frameworks and internal control effectiveness
Prior findings Management confirms issues have been addressed Auditor must verify closure with supporting evidence, not a simple assurance statement
Control testing Largely a design and documentation check Operating effectiveness tested through sample testing and substantive review
New PSPs No distinct first-year requirement beyond standard audit End-to-end review of AML/CFT and technology risk controls one year after launch
Evidence expectation Policies and procedures on record Evidence the control is documented, consistently applied and traceable through a clear audit trail

Download the complimentary MAS PS-G04 Audit Readiness Guide and prepare your organization for the new regulatory audit expectations.

📘 https://www.pecuniya.com/wp-content/uploads/2026/08/Pecuniya-MAS-PS-G04-Audit-Readiness-Guide.pdf

Note: This comparison reflects Pecuniya’s reading of the PS-G04 Guidelines and is provided as Expert Analysis to aid interpretation. It is not a substitute for the original guideline text.

Detailed Analysis

MAS has indicated that audits should remain risk-based and scaled to each PSP’s size and business model. Even so, every licensed entity should expect close attention to the six areas below.

1. AML/CFT Controls and Financial Crime Risk

Auditors will test the design and operation of your money-laundering and terrorism-financing controls, including:

  • Enterprise-wide risk assessments
  • Customer due diligence procedures
  • Name and sanctions screening
  • Transaction monitoring
  • Suspicious transaction reporting
  • Record-keeping and governance oversight

Expert Analysis: In practice, the enterprise-wide risk assessment is often the weakest link because it is completed once at licensing and rarely refreshed as products, customer segments or geographies change. Treat it as a living document reviewed at least annually.

2. Safeguarding of Customer Monies and Assets

Safeguarding arrangements are a mandatory review area for every PSP. Auditors will confirm that the way relevant monies and customer assets are protected meets the standards set out in the Payment Services Act.

3. Base Capital Compliance

PSPs must be able to demonstrate, on an ongoing basis, that minimum base capital levels and adequate financial resources are being maintained — not only at the point of licensing, but throughout the year.

4. Technology Risk Management and Cyber Resilience

Technology and cyber risk remain a top MAS priority. Auditors are expected to examine:

  • Cyber hygiene practices
  • Access management controls
  • IT resilience and business continuity
  • Security operations
  • Data and infrastructure security
  • Technology governance and software development lifecycle controls

Expert Analysis: Access management is frequently where evidence gaps appear — particularly proof that leaver access was revoked promptly and that privileged access is periodically recertified. Export and retain the relevant logs ahead of the audit window rather than pulling them under time pressure.

5. Accuracy of MAS Regulatory Reporting

Auditors are expected to verify that information submitted to MAS — including relevant PSN04 returns — is both accurate and complete.

6. Remediation of Prior Findings

MAS specifically expects auditors to check whether issues raised in earlier audits or inspections have been properly resolved, with evidence to support closure rather than a simple assurance that the matter has been fixed.

Additional Expectations for Newly Licensed PSPs

PS-G04 introduces extra requirements for newly licensed PSPs, and for existing PSPs adding a newly licensed payment service. One year after operations, or the new service, begin, auditors are expected to carry out an end-to-end review covering AML/CFT controls and technology risk management controls.

These reviews go beyond a design check — auditors are expected to test operating effectiveness through sample testing and substantive review, not simply confirm that a policy exists on paper.

Business Impact

Impact Area What Changes
Operational Evidence collection needs to be built into day-to-day processes, not assembled retrospectively before the audit
Compliance AML/CFT and safeguarding frameworks need periodic self-testing, not just annual review
Technology Access logs, resilience testing records and SDLC documentation need to be audit-ready year-round
Governance Committee papers and board oversight records need to clearly evidence challenge and decision-making
Financial Base capital and financial resource adequacy must be demonstrably monitored on an ongoing basis
Risk Prior findings need a formal tracker through to verified, evidenced closure
Customer Stronger safeguarding and AML/CFT evidence reduces the risk of service disruption from a qualified or adverse audit outcome

Implementation Roadmap

The following roadmap, provided as Expert Analysis, sets out a practical sequence for building PS-G04 readiness ahead of your audit window.

Timeline Activities Owner Deliverables Priority
Immediate Map PS-G04’s six focus areas against current controls and identify obvious gaps Compliance / MLRO Initial gap register High
30 Days Refresh the enterprise-wide AML/CFT risk assessment; consolidate technology risk evidence (access logs, BCP tests) Compliance, Technology Updated risk assessment; evidence pack High
60 Days Track prior audit and inspection findings to closure with supporting evidence; validate safeguarding arrangements Internal Audit, Finance Remediation tracker with evidence Medium
90 Days Conduct an internal dry-run audit against PS-G04 expectations; brief the board and senior management Internal Audit, Board Readiness report; board pack Medium

Audit Readiness Checklist

Task Priority Evidence Required Owner Status
Refresh enterprise-wide ML/TF risk assessment High Signed-off risk assessment document MLRO
Verify customer due diligence files are complete High Sample of CDD files with audit trail Compliance
Confirm sanctions screening logs are retained High Screening system logs and alert dispositions Compliance
Test transaction monitoring alert handling High Alert closure records and escalation notes Compliance
Confirm safeguarding arrangements meet PSA standards High Bank confirmations, trust or insurance documentation Finance
Evidence base capital adequacy through the year Medium Monthly capital adequacy calculations Finance
Export access management logs (joiners, movers, leavers) High Access review and revocation records Technology
Validate BCP and cyber resilience testing Medium Test results and remediation notes Technology
Verify PSN04 returns for accuracy and completeness High Reconciled return data and supporting workings Finance / Compliance
Track prior findings to evidenced closure High Remediation tracker with supporting evidence Internal Audit
Assemble governance committee papers Medium Minutes evidencing challenge and decisions Company Secretary

Top 10 Common Mistakes

Based on Pecuniya’s experience supporting MAS-regulated entities through audit cycles, these are the most frequent avoidable issues.

  1. Treating the risk assessment as a one-off document. It is completed at licensing and never revisited, so it no longer reflects current products or customers. Review it at least annually.
  2. Assuming a policy is the same as a control. Auditors test whether a control operates in practice, not whether a policy exists. Keep operating evidence, not just documents.
  3. Losing track of prior findings. Without a formal tracker, findings get informally “fixed” with no evidence of closure. Maintain a single remediation log.
  4. Inconsistent application across teams. A control that works in one team but not another is a control gap. Standardise procedures and checklists.
  5. Evidence scattered across systems and inboxes. When evidence cannot be located quickly, it looks like the control does not exist. Centralise audit evidence ahead of time.
  6. Access management left unreviewed. Leaver access that is not promptly revoked is a recurring technology risk finding. Schedule periodic access recertification.
  7. Regulatory changes not fully rolled out operationally. Policy updates are made, but front-line procedures and training lag behind. Close the loop with staff training and sign-off.
  8. Safeguarding evidence prepared only at year-end. Safeguarding needs to be demonstrably continuous, not a snapshot. Retain periodic confirmations throughout the year.
  9. PSN04 returns reconciled late. Late reconciliation increases the risk of errors surfacing during the audit itself. Reconcile on a rolling basis.
  10. Board papers that record decisions but not challenge. MAS and auditors look for evidence of effective oversight, not just approval. Minute the questions raised, not only the outcome.

Expert Recommendations

The following recommendations reflect Pecuniya’s professional experience supporting PS-G04 readiness. They are Expert Analysis and industry best practice, not statements of MAS’s regulatory requirements.

  • Run an internal dry-run audit 90 days before your external audit window, scoped to the six PS-G04 focus areas.
  • Assign a single owner for the remediation tracker so prior findings cannot fall through organisational gaps.
  • Build a standing evidence repository, updated monthly, rather than reconstructing evidence under audit pressure.
  • Brief the board on PS-G04 expectations early, since governance oversight itself is now part of what is being tested.
  • Treat technology access management as a recurring control, with quarterly recertification rather than an annual check.

Frequently Asked Questions

What is MAS PS-G04?

PS-G04 is a MAS guideline that sets out expectations for how the annual external audit of licensed payment service providers should be conducted, effective 16 July 2026.

Who does PS-G04 apply to?

PS-G04 applies to all licensed payment service providers under the Payment Services Act, including newly licensed PSPs and those adding a newly licensed payment service.

Does PS-G04 create new filing obligations?

PS-G04 does not remove existing obligations such as appointing an external auditor, lodging Form 4, and submitting an Independent Assurance Report. It expands what the audit itself is expected to test.

What are the six focus areas under PS-G04?

AML/CFT controls, safeguarding of customer monies and assets, base capital compliance, technology risk management and cyber resilience, accuracy of MAS regulatory reporting, and remediation of prior findings.

What additional requirement applies to newly licensed PSPs?

One year after operations or a newly licensed service begins, auditors are expected to conduct an end-to-end review of AML/CFT controls and technology risk management controls.

What does ‘testing operating effectiveness’ mean?

It means auditors verify a control actually functions as intended, typically through sample testing and substantive review, rather than only confirming a policy document exists.

How should prior audit findings be tracked?

Through a formal remediation tracker that records the finding, the corrective action taken, and evidence supporting closure, rather than a verbal or informal assurance.

What evidence can auditors request under PS-G04?

Examples include business model and customer profile information, products and services offered, licensing conditions, regulatory breaches and supervisory actions, outstanding audit findings, enterprise-wide risk assessments, governance committee papers, and previous gap assessments.

Why do most audit observations occur?

In Pecuniya’s experience, most observations arise from incomplete documentation, evidence that cannot be located quickly, inconsistent application of controls, regulatory changes not fully rolled out, and prior findings that were never formally tracked to closure.

How early should a PSP start preparing for a PS-G04 audit?

Preparation should begin well before the audit window opens, ideally 90 days or more, since assembling documented, traceable evidence takes time.

Does PS-G04 change base capital requirements?

PS-G04 does not change the underlying capital requirements, but it reinforces that PSPs must demonstrate ongoing compliance with them, not just compliance at a single point in time.

What is a PSN04 return?

PSN04 is a regulatory return submitted to MAS by licensed payment service providers; PS-G04 expects auditors to verify its accuracy and completeness.

Can Pecuniya help with PS-G04 readiness?

Yes. Pecuniya offers PS-G04 audit readiness assessments, gap analysis, AML/CFT internal audit, technology risk review, and remediation validation for licensed PSPs.

Conclusion

PS-G04 signals that MAS expects licensed payment service providers to run mature, well-documented and demonstrably effective control environments — not only at audit time, but throughout the year.

The six focus areas set out in this guide give a clear map of where auditors will look first: AML/CFT, safeguarding, base capital, technology risk, regulatory reporting accuracy, and remediation of prior findings. Newly licensed PSPs carry an additional obligation to demonstrate operating effectiveness within their first year.

The PSPs that manage this transition smoothly are the ones that treat evidence collection as a continuous discipline rather than a pre-audit scramble. Getting ahead of that expectation, rather than reacting to it, is what separates a smooth audit cycle from a stressful one.

How Pecuniya Can Help

Pecuniya’s compliance advisory team helps PSPs assess audit readiness, strengthen governance and control frameworks, and address the core PS-G04 focus areas — from AML/CFT and safeguarding arrangements to technology risk, cyber resilience and remediation tracking.

Service Area What We Review Outcome for Your Business
Audit Readiness Assessment PS-G04 expectations mapped against current controls, documentation and evidence trail A clear, prioritised view of gaps before external auditors arrive
Gap Analysis Against PS-G04 Policies and control frameworks benchmarked against PS-G04, the Payment Services Act, MAS Notices and industry practice A practical remediation roadmap ranked by risk and regulatory impact
AML/CFT Internal Audit Enterprise-wide ML/TF risk assessments, onboarding, screening, monitoring, reporting and governance Stronger, better-evidenced AML/CFT control effectiveness
Technology Risk Review Technology governance, cybersecurity, access management, resilience and outsourcing oversight Clearer visibility over technology and cyber exposure
Remediation Validation Testing of corrective actions and evidence against prior audit or MAS findings A defensible record of remediation progress for regulators and auditors
Ongoing Internal Audit Programme Risk-based audit planning and continuous assurance throughout the year Compliance treated as a year-round discipline, not an annual scramble

 

With over 20 years of hands-on experience supporting MAS-regulated entities, Pecuniya’s team works alongside licensed PSPs — not just as advisors, but as partners in getting ready for PS-G04. If you would like a clear, prioritized view of where your PSP stands, an Audit Readiness Assessment is a practical place to start.

 

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.